CVE-2026-3677Disclosure(tenda / fh451)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for tenda fh451 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The manipulation of the argument funcname/funcpara1 results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fh451
  • fh451_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-07); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
fh451fh451_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-07: 1Exploit Tool / Code · 2026-03-07: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-08: 103-0703-0803-12
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-071
Exploit1
2026-03-081
Disclosure1
2026-03-121
Disclosure1
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-3677: HIGH] Critical vulnerability in Tenda FH451 1.0.0.9 discovered! Exploit for remote stack-based buffer overflow now public. Stay vigilant and update your systems.#cve,CVE-2026-3677,#cybersecurity https://cvefind.com/CVE-2026-3677

    Post summary

    The tweet announces that CVE-2026-3677, a remote stack-based buffer overflow in Tenda FH451 firmware, now has a publicly available exploit and urges users to update their systems.

    0100076
    599 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3677 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The m..https://nvd.nist.gov/vuln/detail/CVE-2026-3677 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new CVE‑2026‑3677 affecting Tenda FH451 routers has been identified with a CVSS score of 7.4; the text provides basic details and a link to NVD, but lacks a PoC, exploit code, or patch information.

    0000018
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3677 A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The manipulation of the argument funcname/funcpara1 r… https://www.cve.org/CVERecord?id=CVE-2026-3677

    Post summary

    The text announces a new vulnerability (CVE-2026-3677) in Tenda FH451 1.0.0.9, detailing impacted function and argument manipulation, but does not mention PoC, exploit, patch, or active exploitation.

    00000115
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendafh451---
OStendafh451_firmware1.0.0.9--

Explore more